Register
Page 1 of 2 12 LastLast
Results 1 to 15 of 18
  1. #1
    DK Veteran
    Youneselm's Avatar
    Join Date
    Nov 2010
    Posts
    587
    Thanks Thanks Given 
    60
    Thanks Thanks Received 
    399
    Thanked in
    74 Posts

    Default NXP LPC2478 CRP3 PROTECTION FUSE UNLOCK

    This is a method is The Temperature Side channel and heating fault attack!!!
    So manny members asked me in pm how to do it.



    Tampering Techniques

    We can distinguish four major attack categories:

    A. Microprobing techniques can be used to access the chip surface directly, thus we can observe, manipulate, and interfere with the integrated circuit.

    1) Software attacks use the normal communication interface of the processor and exploit security vulnerabilities found in the protocols, cryptographic algorithms, or their implementation.

    2) Eavesdropping techniques monitor, with high time resolution, the analog characteristics of all supply and interface connections and any other electromagnetic radiation produced by the processor during normal operation.

    3) Fault generation techniques use abnormal environmental conditions to generate malfunctions
    in the processor that provide additional access.

    All microprobing techniques are invasive attacks. They require hours or weeks in a specialized laboratory and in the process i decap the packaging. The other three are non-invasive attacks. After we have prepared such an attack for a specific processor type and software version, i can usually reproduce it within seconds on another mcu.

    This is a method is The Temperature Side channel and heating fault attack!!!

    don't forget to thank and reps mate:-)


    Type in YouTube: CRP3 NXP and you wil find it. ITS the first video



    Video is not produced by me;-)
    Dont want a visit from Nxp or anny other Company lawer;-)
    Last edited by Youneselm; 15th December, 2015 at 09:41 AM. Reason: so manny members asked in pm how to do it.

  2. The Following 24 Users Say Thank You to Youneselm For This Useful Post:

    aem (16th November, 2015), bearheroes (17th November, 2015), busaman (15th November, 2015), cubica1 (19th November, 2015), dorofteius (15th November, 2015), elchip (20th November, 2015), erdilmen (5th June, 2019), Faraday (15th November, 2015), hoangtu (27th November, 2015), igorr (8th December, 2015), kaosforall (17th March, 2016), krzakx (19th December, 2015), Maartinj (15th November, 2015), mariusica_boy (15th November, 2015), meteor80 (20th November, 2015), mexanico1971 (27th November, 2015), moky (17th December, 2015), rickymix34 (27th November, 2015), skywoker (15th November, 2015), smt (15th November, 2015), soxten (23rd November, 2015), tiguan (22nd November, 2015), yellowstilo (15th November, 2015), zecas (15th November, 2015)

  3. #2
    V.I.P. Member
    mihaiservice's Avatar
    Join Date
    Dec 2009
    Location
    http://www.quick-tuning.com
    Posts
    1,587
    Thanks Thanks Given 
    162
    Thanks Thanks Received 
    990
    Thanked in
    653 Posts

    Default

    Are your home made work ?
    Full WinOLS user


    Custom ENG/GER OLS file for ​ Tune /DPF / SCR / EGR / TVA / VSA / DTC and more...

  4. #3
    DK Veteran
    Youneselm's Avatar
    Join Date
    Nov 2010
    Posts
    587
    Thanks Thanks Given 
    60
    Thanks Thanks Received 
    399
    Thanked in
    74 Posts

    Default

    Everybody can do it at home mate.;-)

  5. The Following 3 Users Say Thank You to Youneselm For This Useful Post:

    busaman (15th November, 2015), elchip (19th December, 2015), mexanico1971 (1st October, 2018)

  6. #4
    DK Veteran
    busaman's Avatar
    Join Date
    Sep 2009
    Location
    suffolk uk
    Posts
    994
    Thanks Thanks Given 
    96
    Thanks Thanks Received 
    198
    Thanked in
    74 Posts

    Default

    are there any instructions/details ???
    7.31sec@203.3mph

  7. #5
    DK Veteran
    Youneselm's Avatar
    Join Date
    Nov 2010
    Posts
    587
    Thanks Thanks Given 
    60
    Thanks Thanks Received 
    399
    Thanked in
    74 Posts

    Default NXP LPC2478 CRP3 PROTECTION FUSE UNLOCK

    When there is more time, i make how step by step. ITS nothing difficult only patians.;-)
    Take 3.3volt vcc and short it to ground pin. Ticking with the wire
    Last edited by Youneselm; 15th November, 2015 at 02:42 PM.

  8. The Following 6 Users Say Thank You to Youneselm For This Useful Post:

    busaman (15th November, 2015), elchip (19th December, 2015), Ginocar (16th November, 2015), mexanico1971 (27th November, 2015), olegario (26th December, 2015), yellowstilo (15th November, 2015)

  9. #6
    DK Veteran
    Youneselm's Avatar
    Join Date
    Nov 2010
    Posts
    587
    Thanks Thanks Given 
    60
    Thanks Thanks Received 
    399
    Thanked in
    74 Posts

    Default NXP LPC2478 CRP3 PROTECTION FUSE UNLOCK

    99 views 2 thanks?!!
    Chinees friends wil ad this soon on there websites. :-)
    Last edited by Youneselm; 15th November, 2015 at 04:35 PM.

  10. The Following 4 Users Say Thank You to Youneselm For This Useful Post:

    igorr (8th December, 2015), kitnoos2002 (17th December, 2016), olejensen (25th May, 2016), yellowstilo (15th November, 2015)

  11. #7
    DK Veteran
    busaman's Avatar
    Join Date
    Sep 2009
    Location
    suffolk uk
    Posts
    994
    Thanks Thanks Given 
    96
    Thanks Thanks Received 
    198
    Thanked in
    74 Posts

    Default

    so what is the action with the hot air gun can you cook the mcu
    7.31sec@203.3mph

  12. #8
    DK Veteran
    Faraday's Avatar
    Join Date
    May 2012
    Location
    The dark side of the moon
    Posts
    2,509
    Thanks Thanks Given 
    2,063
    Thanks Thanks Received 
    2,104
    Thanked in
    1,082 Posts

    Default

    to open loop.

  13. #9
    DK Veteran elchip's Avatar
    Join Date
    Nov 2009
    Location
    EU
    Posts
    597
    Thanks Thanks Given 
    67
    Thanks Thanks Received 
    260
    Thanked in
    63 Posts

    Default

    Tested work 101%
    Regards
    [I]Automotive Electronics Solutions
    Mercedes-Benz Reverse Development Engineer ...
    Mercedes CFF 2010-2017 CFF all models all modules
    Vediamo help flashing over teamviewer ...
    JLR SDD online + offline ...last official ...


  14. The Following 2 Users Say Thank You to elchip For This Useful Post:

    Faraday (21st November, 2015), mexanico1971 (1st October, 2018)

  15. #10
    Top Poster
    hackgsm's Avatar
    Join Date
    Sep 2009
    Posts
    159
    Thanks Thanks Given 
    79
    Thanks Thanks Received 
    59
    Thanked in
    29 Posts

    Default

    no work with ktag

  16. #11
    DK Veteran
    imcumen's Avatar
    Join Date
    Feb 2009
    Location
    FRANCE
    Posts
    596
    Thanks Thanks Given 
    191
    Thanks Thanks Received 
    121
    Thanked in
    91 Posts

    Default

    Quote Originally Posted by youneselmoukhtari View Post
    99 views 2 thanks?!!
    Chinees friends wil ad this soon on there websites. :-)
    Sorry friend


    I did not have my glasses

    without rancor

    Regards
    Last edited by imcumen; 29th November, 2015 at 01:51 PM.











  17. #12
    DK Veteran
    Youneselm's Avatar
    Join Date
    Nov 2010
    Posts
    587
    Thanks Thanks Given 
    60
    Thanks Thanks Received 
    399
    Thanked in
    74 Posts

    Default NXP LPC2478 CRP3 PROTECTION FUSE UNLOCK

    @Imcumen: you need verry thick glasses.;-)

    Only the video is from Eduardnn mate, not the explaining of the technique that is used.
    The technique itself is very old in the business of failure attack analyse. Doctor Sergei Skorobogatov from Cambridge Universit? teach us all this kind attacks such as Power glitching, heat glitching or optical glitching,ect,..

    If you have done Some study you Will know:-)
    These All are my words and ask the Guy himself for it.
    His name is already on the post as he is the Maker of the video nothing else.

    So whats youre point,
    and the purpose for this comment?

    Check in sector dashboards, tread "Morgan dash".
    You Will see what i do with locked devices.;-)
    We engineers know that this solution is an old trick in the fault generating technique, if you know what you are doing.
    I can explain it if you ask for it.;-)
    But not in pm, only here on forum-board.
    So everyone wil learn from it.
    It Will be good for every member.

    Have dig in my old study Books and maps. This is for the good thinking brain people out here;-)
    I put link here from a workshop from my old teacher-professor ho teach me allot, and made me a good engineer.

    Look in this sector in tread: PHISYCAL attacks on TAMPER resitance, ect ...
    Last edited by Youneselm; 13th December, 2015 at 01:32 PM.

  18. The Following User Says Thank You to Youneselm For This Useful Post:

    busaman (29th November, 2015)

  19. #13
    DK Veteran
    Youneselm's Avatar
    Join Date
    Nov 2010
    Posts
    587
    Thanks Thanks Given 
    60
    Thanks Thanks Received 
    399
    Thanked in
    74 Posts

  20. #14
    DK Veteran
    Youneselm's Avatar
    Join Date
    Nov 2010
    Posts
    587
    Thanks Thanks Given 
    60
    Thanks Thanks Received 
    399
    Thanked in
    74 Posts

    Default

    This technique called" The Temperature Side channel and heating fault attack", and is explained in this document, for those ho dont understand wath is going on in this video. If you have Some questions about topic feel free to ask.;-)

    https://eprint.iacr.org/2014/190.pdf

  21. The Following 2 Users Say Thank You to Youneselm For This Useful Post:

    igorr (9th December, 2015), zyjekrc51 (21st December, 2015)

  22. #15
    DK Veteran
    Youneselm's Avatar
    Join Date
    Nov 2010
    Posts
    587
    Thanks Thanks Given 
    60
    Thanks Thanks Received 
    399
    Thanked in
    74 Posts

  23. The Following 2 Users Say Thank You to Youneselm For This Useful Post:

    igorr (9th December, 2015), mexanico1971 (1st October, 2018)

 

 
Page 1 of 2 12 LastLast

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
This website uses cookies
We use cookies to store session information to facilitate remembering your login information, to allow you to save website preferences, to personalise content and ads, to provide social media features and to analyse our traffic. We also share information about your use of our site with our social media, advertising and analytics partners.